StackRadar

CVE-2025-54388

Medium

Advisory

Published 29 Jul 2025In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
4.6
base score, highest
EPSS
0.002
12th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
10
of 17,781 indexed, latest versions
Container images
9
deployed by those charts
Fix available
1 of 1
affected package

Moby firewalld reload makes published container ports accessible from remote hosts

Carried by container images the latest versions of 10 of 17,781 indexed charts deploy, on 9 images.

Affected packageAffected versionsFixed inImages
github.com/docker/dockergolangv28.2.1, v28.2.2+incompatible, v28.3.0+incompatible, v28.3.2+incompatible28.3.39
OSV records
GHSA-x4rx-4gw3-53p4
Also known as
GO-2025-3830

Charts affected

10 by stars
ChartLatestAffected imagesRadar Score
coreinstill-aiOfficialVerified publisher0.1.751 of 15See more

core instill-ai 0.1.75

1 of the 15 container images this version deploys carry CVE-2025-54388.

Container imageDigestPackageFixed in
openfga/openfga:v1.9.25e94966c11df
github.com/docker/docker@v28.2.2+incompatible
28.3.3

Open the chart page →

30,816
lagoon-remotelagoon-chartsVerified publisher0.106.01 of 1See more

lagoon-remote lagoon-charts 0.106.0

1 of the 1 container images this version deploys carry CVE-2025-54388.

Container imageDigestPackageFixed in
uselagoon/docker-host:v3.6.12c89ed939b8b
github.com/docker/docker@v28.2.1
28.3.3

Open the chart page →

2,113
caninecanine0.1.101 of 7See more

canine canine 0.1.10

1 of the 7 container images this version deploys carry CVE-2025-54388.

Container imageDigestPackageFixed in
ghcr.io/caninehq/canine:latesta058034ca006
github.com/docker/docker@v28.3.0+incompatible
28.3.3

Open the chart page →

14,130
pyroscope-monitoringgrafana0.1.11 of 6See more

pyroscope-monitoring grafana 0.1.1

1 of the 6 container images this version deploys carry CVE-2025-54388.

Container imageDigestPackageFixed in
grafana/otel-lgtm:0.11.1009d8c3ce4f3a
github.com/docker/docker@v28.2.2+incompatible
28.3.3

Open the chart page →

8,188
kube-ovnkube-ovn-test1.14.01 of 1See more

kube-ovn kube-ovn-test 1.14.0

1 of the 1 container images this version deploys carry CVE-2025-54388.

Container imageDigestPackageFixed in
kubeovn/kube-ovn:v1.14.06722b54eb5c0
github.com/docker/docker@v28.2.2+incompatible
28.3.3

Open the chart page →

4,940
kubiya-runnerkubiya-helm-chartsOfficialVerified publisher0.9.41 of 9See more

kubiya-runner kubiya-helm-charts 0.9.4

1 of the 9 container images this version deploys carry CVE-2025-54388.

Container imageDigestPackageFixed in
ghcr.io/kubiyabot/tool-manager:0.5.80cca6760763a
github.com/docker/docker@v28.3.2+incompatible
28.3.3

Open the chart page →

20,204
lagoon-docker-hostlagoon-chartsVerified publisher0.7.01 of 1See more

lagoon-docker-host lagoon-charts 0.7.0

1 of the 1 container images this version deploys carry CVE-2025-54388.

Container imageDigestPackageFixed in
uselagoon/docker-host:v3.6.12c89ed939b8b
github.com/docker/docker@v28.2.1
28.3.3

Open the chart page →

2,113
lensoci-ai-incubations0.1.141 of 16See more

lens oci-ai-incubations 0.1.14

1 of the 16 container images this version deploys carry CVE-2025-54388.

Container imageDigestPackageFixed in
quay.io/prometheus/prometheus:v3.5.063805ebb8d2b
github.com/docker/docker@v28.2.2+incompatible
28.3.3

Open the chart page →

17,070
parcaparca-rr0.1.01 of 2See more

parca parca-rr 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-54388.

Container imageDigestPackageFixed in
ghcr.io/parca-dev/parca:v0.24.23776500fde82
github.com/docker/docker@v28.2.2+incompatible
28.3.3

Open the chart page →

2,366
spindlerubxkubeVerified publisher0.1.11 of 2See more

spindle rubxkube 0.1.1

1 of the 2 container images this version deploys carry CVE-2025-54388.

Container imageDigestPackageFixed in
ghcr.io/qjoly/spindle:v1.16.1-alphaaab0c99d313f
github.com/docker/docker@v28.2.2+incompatible
28.3.3

Open the chart page →

1,438

Container images carrying it

9 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
uselagoon/docker-host:v3.6.12c89ed939b8b
github.com/docker/docker@v28.2.1
28.3.3
2
grafana/otel-lgtm:0.11.1009d8c3ce4f3a
github.com/docker/docker@v28.2.2+incompatible
28.3.3
1
kubeovn/kube-ovn:v1.14.06722b54eb5c0
github.com/docker/docker@v28.2.2+incompatible
28.3.3
1
openfga/openfga:v1.9.25e94966c11df
github.com/docker/docker@v28.2.2+incompatible
28.3.3
1
ghcr.io/caninehq/canine:latesta058034ca006
github.com/docker/docker@v28.3.0+incompatible
28.3.3
1
ghcr.io/kubiyabot/tool-manager:0.5.80cca6760763a
github.com/docker/docker@v28.3.2+incompatible
28.3.3
1
ghcr.io/parca-dev/parca:v0.24.23776500fde82
github.com/docker/docker@v28.2.2+incompatible
28.3.3
1
ghcr.io/qjoly/spindle:v1.16.1-alphaaab0c99d313f
github.com/docker/docker@v28.2.2+incompatible
28.3.3
1
quay.io/prometheus/prometheus:v3.5.063805ebb8d2b
github.com/docker/docker@v28.2.2+incompatible
28.3.3
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.